Commit Graph

  • 494f73369a Every test passes the typecheck gate jschoubben 2026-09-17 22:53:34 +02:00
  • 27b5f8d092 The bed passes the typecheck gate jschoubben 2026-09-17 22:52:31 +02:00
  • b77d03a1f8 readFileSync is imported, not assumed jschoubben 2026-09-17 22:48:34 +02:00
  • 48f8fe6168 The settle check records settling instead of inferring it from the clock jschoubben 2026-09-17 22:39:48 +02:00
  • 158fe5c327 Apply the bed review: one buildable consumer, honest gates, tighter plumbing jschoubben 2026-09-17 22:39:49 +02:00
  • 428f13bfae The settle check records settling instead of inferring it from the clock jschoubben 2026-09-17 22:39:48 +02:00
  • d3a6dc9784 The bed adopts only what genesis leaves it: the broker jschoubben 2026-09-17 22:23:13 +02:00
  • bfd70e9e57 The no-fake multi-node bed: two machines, everything built by the mesh itself jschoubben 2026-09-17 22:15:34 +02:00
  • e3d96d9fa9 Merge pull request 'Remove the inert MESH_SEAL_KEY; cite ADR 0048 correctly' (#30) from cleanup/seal-key-tombstones into main jschoubben 2026-09-17 22:02:45 +02:00
  • 2438883a5f Remove the inert MESH_SEAL_KEY, and cite the ADR that retired it correctly jschoubben 2026-09-17 22:02:31 +02:00
  • 1e4713c311 Merge pull request 'two-node-db on the one-store model: store cross-node proven end-to-end' (#29) from multi-node/one-store-beds into main jschoubben 2026-09-17 09:54:43 +02:00
  • 0e382f1db7 two-node-db is GREEN on the one-store model — store cross-node proven end-to-end jschoubben 2026-09-17 09:53:35 +02:00
  • d8540bec42 Convert two-node-db to the one-store model (WIP: blocked on issue 058) jschoubben 2026-09-17 09:00:33 +02:00
  • a8afe5ce53 Merge pull request 'A two-node bed: a joined node opens the adopted broker over the overlay' (#28) from multi-node/cross-node-bed into main jschoubben 2026-09-17 01:44:53 +02:00
  • b6bf31d4e6 The cross-node bed is green: push the provider node after adding the remote consumer jschoubben 2026-09-17 01:34:22 +02:00
  • 155800bc9a A two-node bed: a joined node opening the adopted broker over the overlay (055) jschoubben 2026-09-17 01:01:54 +02:00
  • 03d036cbeb Merge pull request 'One-node bed: SDK-by-version, rename, and the store/broker upgrade proofs' (#27) from feat/a-bed-that-hands-over-nothing into main jschoubben 2026-09-16 23:25:34 +02:00
  • 440e2653b2 Phase 3.3/3.4: prove the store and broker upgrade in place, through the window jschoubben 2026-09-16 21:51:20 +02:00
  • 70c1545161 Phase 3.2: lavinmq declares no network — it adopts mesh-broker jschoubben 2026-09-16 21:33:16 +02:00
  • 5d6e8fbe7a Rename mesh-control -> mesh-controller, substrate -> foundation jschoubben 2026-09-16 18:40:40 +02:00
  • 49b80d8516 The one-node bed supervises the host as a service, so reboot is a real check jschoubben 2026-09-16 16:20:44 +02:00
  • f57e05e75e The one-node bed places at the site it operates, and tolerates the CP recreating jschoubben 2026-09-16 14:10:26 +02:00
  • eff91742e8 The bed publishes the SDK before the base build jschoubben 2026-09-16 10:27:37 +02:00
  • 61abeb7f6b The lab stocks the full catalogue, not the bootstrap three jschoubben 2026-09-16 01:01:19 +02:00
  • 09a22de78f The lab answers the installer's questions the unattended way jschoubben 2026-09-15 21:57:26 +02:00
  • e451a9191a The lab names the modules as the catalogue does jschoubben 2026-09-15 20:51:00 +02:00
  • fce554d150 A run-once step leaves nothing to ask, and V4 asked anyway jschoubben 2026-09-15 01:35:42 +02:00
  • 1425f5e7d4 Verify every resource kind, not the one I kept looking at jschoubben 2026-09-15 00:46:05 +02:00
  • 3ebf0bb38c Containers coming back is not the mesh coming back jschoubben 2026-09-14 23:44:24 +02:00
  • 9b8b21ac17 E1 moves the module's source for real jschoubben 2026-09-14 23:36:05 +02:00
  • 475fd9a088 Register the firewall before assigning it jschoubben 2026-09-14 22:52:26 +02:00
  • f132a4bcbd The packet filter is a module too, and it was assigned to nothing jschoubben 2026-09-14 22:45:52 +02:00
  • 6b482ee7dc Assigning networking is not being on the network jschoubben 2026-09-14 22:26:04 +02:00
  • d0d56782a0 Split describing the mesh from the catalogue holding it jschoubben 2026-09-14 22:17:06 +02:00
  • 3690e17cf4 Ask the catalogue as the only thing that is allowed to jschoubben 2026-09-14 22:08:52 +02:00
  • 572aae2eb4 A plan with codes, stated up front and reported against jschoubben 2026-09-14 22:00:13 +02:00
  • 2f470f27b8 Genesis makes six claims; assert them separately jschoubben 2026-09-14 21:58:58 +02:00
  • 7641bb2059 A one-node mesh, and twelve things that have to be true of it jschoubben 2026-09-14 21:52:24 +02:00
  • 9146f30859 Name the container, and issue the account jschoubben 2026-09-14 21:20:57 +02:00
  • c3d5ec1d55 Build each repository from its own ref, and build the provider jschoubben 2026-09-14 21:05:28 +02:00
  • f04911a763 Give the module the broker it asks for, rather than a module that asks for nothing jschoubben 2026-09-14 20:56:35 +02:00
  • 4ef0a19053 A manifest the control plane can open, and stop swallowing the failure when it cannot jschoubben 2026-09-14 20:46:11 +02:00
  • babf08b9f8 Raise machines that are somebody, and a bed that hands over nothing jschoubben 2026-09-14 20:41:55 +02:00
  • 7fa1f1f0bb Merge pull request 'One archive per machine, not one per image' (#26) from fix/the-lab-ships-runtimes-not-toolchains into main jschoubben 2026-09-14 19:58:20 +02:00
  • 5d1f7762c2 One archive per machine, not one per image jschoubben 2026-09-14 19:58:01 +02:00
  • 8fca04f560 Merge pull request 'Configure the resolver rather than fight it' (#25) from fix/configure-the-resolver-rather-than-fight-it into main jschoubben 2026-09-14 18:45:58 +02:00
  • fa5e5cb912 Configure the resolver rather than fight it jschoubben 2026-09-14 18:45:40 +02:00
  • eed5647146 Merge pull request 'One dropped lookup should not cost a two-hour run' (#24) from fix/one-dropped-lookup-should-not-cost-a-run into main jschoubben 2026-09-14 18:23:49 +02:00
  • ea0a7f7e64 One dropped lookup should not cost a two-hour run jschoubben 2026-09-14 18:23:25 +02:00
  • fe50f33023 Merge pull request 'The beds place the builder's manifest too' (#23) from feat/installation-sets-up-the-builder into main jschoubben 2026-09-14 12:32:17 +02:00
  • fb6dab6a48 The beds place the builder's manifest too jschoubben 2026-09-14 12:31:44 +02:00
  • 36a5ad758b Merge pull request 'The beds raise a mesh through an installer that carries a builder' (#22) from feat/a-module-is-a-repository-and-a-path into main jschoubben 2026-09-13 11:17:29 +02:00
  • d27f24cf3e The bed resolves an artifact the way the builder would jschoubben 2026-09-13 04:56:00 +02:00
  • fb18807000 The bed checks the control plane was built, not carried jschoubben 2026-09-13 04:28:54 +02:00
  • 607ea241c7 The lab's installer carries a builder, and genesis is told what to build jschoubben 2026-09-13 04:24:18 +02:00
  • 1ba237a634 Stage the sdk from its own checkout, not from a symlink that may not be one jschoubben 2026-09-13 02:55:24 +02:00
  • 7cb53d5092 Merge pull request 'Raise a mesh of one by the installer, in a bed of its own' (#21) from feat/a-module-is-a-repository-and-a-path into main jschoubben 2026-09-12 16:54:28 +02:00
  • e427e41389 Raise a mesh of one by the installer, in a bed of its own jschoubben 2026-09-12 16:46:05 +02:00
  • 06d22320f8 Merge pull request 'The provider remap moves a port; it does not bind it to loopback' (#20) from fix/the-remap-moves-a-port into main jschoubben 2026-09-11 22:34:41 +02:00
  • 3f58a0a08f The provider remap moves a port; it does not bind it to loopback jschoubben 2026-09-11 22:05:18 +02:00
  • 6ed5fdb3c2 Merge pull request 'Delete the lab's registry, and bootstrap the anchor through the installer' (#19) from feat/bed-bootstraps-through-the-installer into main jschoubben 2026-09-11 21:57:04 +02:00
  • 555401a787 The bed bootstraps through the installer, not around it jschoubben 2026-09-11 11:46:42 +02:00
  • 6c09ddb528 An image the machine has no account for is handed over, not fetched jschoubben 2026-09-11 01:11:18 +02:00
  • d637c77f08 An image id belongs to the machine holding it, so ask the machine jschoubben 2026-09-11 00:02:56 +02:00
  • 94e617915c The home segment moves off 192.168.1.0/24 jschoubben 2026-09-11 00:00:19 +02:00
  • a4c2a9b90b The routing record is 0066, not 0056 jschoubben 2026-09-10 23:35:35 +02:00
  • 7875145c0e An unpinned tag is a finding, not a reason to stop the bed jschoubben 2026-09-10 23:17:57 +02:00
  • 675facdb0d The beds name images the way a machine would find them jschoubben 2026-09-10 23:16:41 +02:00
  • 5c91c0ecd2 Scenarios: egress where images are needed, and images: cut to what is ours jschoubben 2026-09-10 23:16:23 +02:00
  • 751948f0f9 The lab had a registry that production does not, so it tested a fiction jschoubben 2026-09-10 23:16:05 +02:00
  • 0a0c57b610 whole-mesh-full: the CA root a person hands the mesh must be readable by it jschoubben 2026-09-10 22:35:49 +02:00
  • a48b60b604 whole-mesh-full: the bed knows about ADR 0056 jschoubben 2026-09-10 21:06:10 +02:00
  • 2f4cb871d9 A raise does not finish until the machines can pull from the registry jschoubben 2026-09-10 21:05:52 +02:00
  • d9bf178546 whole-mesh-full: serve the internal CA's image jschoubben 2026-09-10 21:05:30 +02:00
  • 80b0670ebe whole-mesh-full: the real segmented topology, and the overlay proven across the access point jschoubben 2026-09-09 11:17:00 +02:00
  • a5f53f524a Merge pull request 'whole-mesh rehearsal beds: the real node sets converge on one substrate' (#18) from feat/whole-mesh into main jschoubben 2026-09-08 20:06:19 +02:00
  • 591f2a641c whole-mesh-full: prove the dry-run fixes (fail2ban hostable, credential own-secrets) jschoubben 2026-09-08 20:05:04 +02:00
  • fcdcd338c0 Add whole-mesh full three-node bed (stage 3: both server sets, one substrate) jschoubben 2026-09-08 18:22:56 +02:00
  • 90651e1e73 Add whole-mesh ace dry-run bed (stage 2 of whole-mesh rehearsal) jschoubben 2026-09-08 00:19:52 +02:00
  • 581fd6da77 Add whole-mesh novox dry-run bed (stage 1 of whole-mesh rehearsal) jschoubben 2026-09-07 22:54:10 +02:00
  • 239ca1520c Merge pull request 'local-model bed: prove model-access answered by a node (ADR 0055)' (#17) from feat/local-model into main jschoubben 2026-09-07 05:26:05 +02:00
  • cf26b19b96 local-model bed: prove model-access answered by a node (ADR 0055) jschoubben 2026-09-07 05:25:21 +02:00
  • 7d7583350c Merge pull request 'openai bed: prove the static-key model-access path (ADR 0050)' (#16) from feat/openai-access into main jschoubben 2026-09-07 04:25:59 +02:00
  • a1231a7f89 openai bed: prove the static-key model-access path (ADR 0050) jschoubben 2026-09-07 04:25:26 +02:00
  • 0513163119 Merge pull request 'model-usage bed: prove the usage store end to end (ADR 0054)' (#15) from feat/usage-store into main jschoubben 2026-09-07 04:08:24 +02:00
  • 9cc3c1ac2a model-usage bed: prove the usage store end to end (ADR 0054) jschoubben 2026-09-07 04:07:41 +02:00
  • 8313e78325 Merge pull request 'anthropic bed: end-to-end model-access refreshable-grant, with per-module dep packaging' (#14) from feat/anthropic-bed into main jschoubben 2026-09-07 02:48:54 +02:00
  • 87c4820130 anthropic bed: package a module's own npm deps, stage grant files readably jschoubben 2026-09-07 02:47:50 +02:00
  • 71bea08f3b anthropic-bed: prove the host unseals the refresh token, no node-key stub jschoubben 2026-09-07 01:55:28 +02:00
  • 6be5072565 anthropic-bed: prove model-access refreshes on the manager node jschoubben 2026-09-07 01:00:37 +02:00
  • 0a132aa00e Merge pull request 'lavinmq-bed: prove the AMQP provider provisions a require-only consumer' (#13) from feat/lavinmq-bed into main jschoubben 2026-09-06 23:21:48 +02:00
  • f04c4ba3be lavinmq-bed: GREEN — AMQP provider provisions a require-only consumer's vhost (mint fix) jschoubben 2026-09-06 23:20:59 +02:00
  • 73bd086193 lavinmq-bed: reproduces a credential-mint gap for require-only consumers of a parameterless provision jschoubben 2026-09-06 16:09:01 +02:00
  • 8e494c0e78 Add lavinmq-bed: a two-node amqp provider + consumer bed jschoubben 2026-09-06 15:50:33 +02:00
  • b22a1716d6 Merge pull request 'route-forwarding: prove the native ingress routes + withdraws (drop traefik)' (#12) from feat/route-proxy-bed into main jschoubben 2026-09-06 15:17:24 +02:00
  • 6cd595d403 route-forwarding: GREEN — slug hello-web so it resolves; Host-routing + withdrawal proven jschoubben 2026-09-06 15:16:56 +02:00
  • f03647d605 Add route-forwarding lab bed proving the route grant end to end jschoubben 2026-09-06 15:07:23 +02:00
  • b75ec7782d Merge pull request 'schedule-tick: prove a scheduled container fires on its cadence (ADR 0053)' (#11) from feat/schedule-tick into main jschoubben 2026-09-06 14:27:46 +02:00
  • 76ecbaed85 lab: a scheduled container fires on its cadence without gating (ADR 0053) jschoubben 2026-09-06 14:20:54 +02:00
  • 399549db36 Merge pull request 'Two-node DB-consumer bed (GREEN) + scenario disk field' (#10) from feat/two-node-db-consumer into main jschoubben 2026-09-06 13:48:43 +02:00